* The importance of independent validation and verification
Vendors with extant systems management implementations such as Marimba, Unicenter, OpenView or SMS have found considerable success in the monitoring and remediation of systems through automated software distribution.
This ability is especially useful for continuously monitoring the various software manufacturers for vulnerability and system-patch updates, automatically downloading them and applying them. This so-called “level-setting” of the enterprise has bearing upon business service management and speaks to ITIL’s best-practices recommendations.
Even though these systems management tools have brought us much closer to systematic and timely across-the-board updating, it seems there is still a gaping hole – one that has enormous cost and security implications if left unchecked. Consider: An end user, not in IT but with technical talent, gains administrative access to the local computer (freely given out in many organizations, but easily acquired even in those shops that closely guard such things) and simply downloads and installs whatever software he thinks he needs. Or how about this: Basic end users download and install a variety of “free” software packages, some innocuous (such as WebShots – doubtless one of the most popular free downloads on the Web), some loaded with potentially damaging adware and spyware.
Now suppose that the internal applications development department, responsible for a wide array of important internally developed business applications, writes an update or patch for a given system – one of the many patches or updates that systems managers readily push out to users with systems management software distribution techniques. But the update has flaws. Perhaps it overwrites key system DLLs or accidentally updates the wrong registry key, bringing systems to a halt or making them completely unreliable.
All of the above scenarios, and others, point to the fact that while the IT organization can somewhat control rogue installations of software through policies, and enterprise installations of software can be managed through high-quality systems management tools, at the end of the day changes in most environments can slip through without any IT person’s awareness.
The implications should not be lost on any IT manager. The potential for the introduction of security vulnerabilities, coupled with the need to physically remediate the machines using expensive IT technician support is quite evident. It is precisely this provocative gap that needs to be filled. Clearly, there has to be some sort of watchdog able to automatically handle such incidents and report back to IT stakeholders.
In the human world, there are those in the business of monitoring IT projects being undertaken by contractors on behalf of a given IT entity. The term given to this monitoring effort is independent validation and verification (IV&V). For example, a state agency where I recently worked is using a company called SysTest for IV&V while Avanade rewrites a critical state-related service application. SysTest “red- flags” areas in which either the agency or Avanade has an issue, and has tremendously helped with the forward movement of the service application.
This same IV&V idea exists in software automation designed to act as an ancillary component to conventional systems management tools. Two companies in this area, Reflectent and Tripwire, specialize in watching systems – that is, servers and desktops (and in Tripwire’s case network gear as well) – for unauthorized and unexpected changes. While neither package actually fixes the problem, they both alert IT.
The advantages are obvious and, from the perspective of total cost of ownership and security, tremendous. In the application development department example above, the error could be pointed out well before it causes an enterprise-class problem, and it gives IT the chance to come up with ways to remediate the issue. Finger-pointing frequently takes place and sucks valuable cycles away from problem determination and resolution. IV&V software dramatically reduces this phenomenon because it precisely points to the source of system problems.
No organization should consider its change management paradigm complete until it has implemented some sort of automated IV&V monitoring that is able to spot those unauthorized and unexpected changes – especially for those hard-to-find but pervasive changes that are so common throughout the computing world.
As always, I would love to hear your ideas and input.




